/etc/cron.allow exists on a host and contains only the line `alice`. /etc/cron.deny exists too and lists `bob`. Which users may run crontab?

LPIC-1 Exam 102-500, objective 107. Administrative tasks hard

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Not correct Every user except bob, because cron.deny takes effect first

Wrong. The order is the other way round: cron.deny is consulted only when cron.allow does not exist. With cron.allow present, cron.deny is ignored entirely.

Not correct No user at all, because the two files contradict each other

Wrong. The rule is a strict precedence, not a conflict. Nothing is disabled by having both files present.

Correct Only alice, because cron.allow exists and cron.deny is then ignored

Correct. If /etc/cron.allow exists, only the users named in it may use crontab, and /etc/cron.deny is not consulted. root is normally exempt from these restrictions.

Not correct alice and bob, because being named in either file grants access

Wrong. cron.deny lists users who are refused, never users who are granted. Naming someone there can only take access away.

Why

The rule: if /etc/cron.allow exists, it is an exclusive whitelist and /etc/cron.deny is ignored. If cron.allow does not exist, everyone may use crontab except users listed in cron.deny. If neither file exists, behaviour depends on the build — many distributions then allow only root. at uses the identical scheme with /etc/at.allow and /etc/at.deny.

Where this comes from

Cited
LPI exam objective 107.2
What it says
Configure user access to cron and at services.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 107 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500